Pages: [1] 2
Author Topic: Security for files, dissuading potential piracy, I have Ideas, need help plz  (Read 15755 times)
DMVDUB
Newbie
*

Karma: +0/-8
Offline Offline

Posts: 20



I've been dialing in a few different files specific to certain 1.8t turbo configurations and as I've been able to give a couple people I trust files that they can use, and report information back to me in return without worry.

I really have no intention of making some tuning company or any of that, I would just like some Ideas and throw out some ideas for protection of software EULA nullification aka PIRACY.

I'll just give a numbered list of ideas and questions,

1. Is there a way I could name a file and have that name change if it's reflashed to another ECU? Potentially something instead of EXAMPLE NAME SW 1.8T it would read STOLEN SW CONTACT email or phone# ? I have no idea how I could possibly trigger this without some expensive encryption or mating hardware / SW...

2. Could I code it to a certain VIN or Cluster causing a possible Custom MIL / CEL reading like the above, STOLEN SOFTWARE / HARDWARE / DO NOT PASS INSPECTION / CONTACT XX?

3. What can I do to make the files I send out secure?

4. I would really like it to cause something insane like have the alarm go off, flashing lights, horn, car won't start, ECU reads UNAUTHORIZED USER CONTACT XX!

5. I am also interested in marking / branding my files. I'm more concerned of someone else using them for profit if I'm not. I have a certain person in mind who I already know wants my files and has tried bribing my test subjects for the .bin. I know I can put NO READ put my signature , logo, filename, whatever in the open space on immo-defeated ecus as well as change the regular ECU name, but is there a way of doing this that will completely destroy the file if this "brand" is changed? I would be using a description of the file, the persons name who received it, the date and then a number designation that only means something in my records.

Any ideas on this?

EDIT- another idea, a possible way of causing the car to perform in stock form or a soft limp?
« Last Edit: December 24, 2013, 10:45:42 PM by DMVDUB » Logged
ddillenger
Hero Member
*****

Karma: +639/-21
Offline Offline

Posts: 5640



If someone wants your file, they're going to get it. There is nothing that you can do about it.

What you're referring to could (some of it) be accomplished with custom code. That being said, you're going to have to link the file to something, and the eeprom is about your only option. That's easy enough to copy as well.

When you start adding malicious code into someone's ecu, you're opening up a whole new can of worms.
Logged

Please, ask all questions on the forums! Doing so will ensure the next person with the same issue gets the opportunity to learn from your experience!

Email/Google chat:
DDillenger84(at)gmail(dot)com

Email>PM
manfred
Newbie
*

Karma: +0/-0
Offline Offline

Posts: 12



you can noread write in the file, but that's easy to manipulat
it's not a problem for profis
Logged
nyet
Administrator
Hero Member
*****

Karma: +604/-166
Online Online

Posts: 12234


WWW

I think you are overestimating the value of your file at this point.
Logged

ME7.1 tuning guide (READ FIRST)
ECUx Plot
ME7Sum checksum checker/corrrector for ME7.x

Please do not ask me for tunes. I'm here to help people make their own.

Do not PM me technical questions! Please, ask all questions on the forums! Doing so will ensure the next person with the same issue gets the opportunity to learn from your experience.
DMVDUB
Newbie
*

Karma: +0/-8
Offline Offline

Posts: 20



I think you are overestimating the value of your file at this point.

Why is that? Because I have 3 posts in Nefmote?  Roll Eyes

Not everyone gets on the forum to talk about what they're doing. Some of us just, DO.

Makes me think of the saying, those who can't do teach... those who can, DO.

I have a high knowledge of the mechanical aspect and I've learned quite a bit when it comes to tuning , so I'm able to put the two together. If my files weren't worth something I wouldn't have a company over my shoulder trying to pay my test subjects for my tune.

Logged
cerips
Full Member
***

Karma: +3/-2
Offline Offline

Posts: 118



Your code will be running on a non-secure system you have no control over.
You can make it harder for people to reverse engineer what you've done to stop them or stop the casual hacker.

To prove it's your code you could hide a code in it by using varying versions of processor instructions that achieve the same outcome, I'm sure I saw some papers on this.
Logged
ddillenger
Hero Member
*****

Karma: +639/-21
Offline Offline

Posts: 5640



At this point, it's easy to believe you're special, if only because you simply don't know what you don't know. Maybe, if you're really lucky, you'll get the opportunity to talk to a real professional. It'll be an eye opening experience.

This is not to be taken as an insult. It's great that you're interested in learning, and hopefully someone here can benefit from your experience. I can tell you with certainty however that anyone with something worth the protection you're talking about wouldn't have to ask this question.
Logged

Please, ask all questions on the forums! Doing so will ensure the next person with the same issue gets the opportunity to learn from your experience!

Email/Google chat:
DDillenger84(at)gmail(dot)com

Email>PM
littco
Hero Member
*****

Karma: +52/-7
Offline Offline

Posts: 903



I've been dialing in a few different files specific to certain 1.8t turbo configurations and as I've been able to give a couple people I trust files that they can use, and report information back to me in return without worry.

I really have no intention of making some tuning company or any of that, I would just like some Ideas and throw out some ideas for protection of software EULA nullification aka PIRACY.

I'll just give a numbered list of ideas and questions,

1. Is there a way I could name a file and have that name change if it's reflashed to another ECU? Potentially something instead of EXAMPLE NAME SW 1.8T it would read STOLEN SW CONTACT email or phone# ? I have no idea how I could possibly trigger this without some expensive encryption or mating hardware / SW...

2. Could I code it to a certain VIN or Cluster causing a possible Custom MIL / CEL reading like the above, STOLEN SOFTWARE / HARDWARE / DO NOT PASS INSPECTION / CONTACT XX?

3. What can I do to make the files I send out secure?

4. I would really like it to cause something insane like have the alarm go off, flashing lights, horn, car won't start, ECU reads UNAUTHORIZED USER CONTACT XX!

5. I am also interested in marking / branding my files. I'm more concerned of someone else using them for profit if I'm not. I have a certain person in mind who I already know wants my files and has tried bribing my test subjects for the .bin. I know I can put NO READ put my signature , logo, filename, whatever in the open space on immo-defeated ecus as well as change the regular ECU name, but is there a way of doing this that will completely destroy the file if this "brand" is changed? I would be using a description of the file, the persons name who received it, the date and then a number designation that only means something in my records.

Any ideas on this?

EDIT- another idea, a possible way of causing the car to perform in stock form or a soft limp?

Quite frankly even if someone did take your protected theoretical tune, all they need to do is take the relevant maps and copy them over to a fresh map.. Plenty of software out there that will facilitate this X comparison... And then it's almost impossible to prove anything!

Sorry but trust me, it ain't worth the hassle.. Boot mode read will get you all the info you need.

IMHO concentrate on getting a credible name in tuning, it's offers far more "protection" than any hackable coding!









Logged
littco
Hero Member
*****

Karma: +52/-7
Offline Offline

Posts: 903



I think you are overestimating the value of your file at this point.

Have you seen the map it's competing against? Unbelievable ....

« Last Edit: December 25, 2013, 04:17:48 PM by littco » Logged
DMVDUB
Newbie
*

Karma: +0/-8
Offline Offline

Posts: 20



This is the most closed minded group of self proclaimed "smart people" I've ever seen...


If I ask a question about ideas in security, that means I don't know how to write a solid file?

Sorry, but designing a file for a specific platform, to perform a specific way has NOTHING to do with security.

So saying my file isn't good because I want to know security options is just dumb.

I don't need to speak to any of the tuners you call true professionals. My files are very good, The people using them have used the "best" tunes on the market and mine outperforms them in EVERY way imaginable.

I'm done with you fûcking nerds. I'll get back to getting my hand dirty, and seriously all the security needed is that the people I deal with know me and know I have no tolerance for stealing, bullshittîng me or any lies.

Bye NERDS. Guarantee 90% of you can't tune worth a damn, you come on here talk crap and spit theory. If you were so great you'd be a PROFESSIONAL

Logged
nyet
Administrator
Hero Member
*****

Karma: +604/-166
Online Online

Posts: 12234


WWW

First off, copy protection isn't "security"

What it is is a waste of time on this ancient platform.

If you really think it is worth the trouble, make a daughter card with an FPGA and a bunch of custom map encryption code.

Finally, nobody is claiming anything about their own ability or intelligence except yourself.

Logged

ME7.1 tuning guide (READ FIRST)
ECUx Plot
ME7Sum checksum checker/corrrector for ME7.x

Please do not ask me for tunes. I'm here to help people make their own.

Do not PM me technical questions! Please, ask all questions on the forums! Doing so will ensure the next person with the same issue gets the opportunity to learn from your experience.
ddillenger
Hero Member
*****

Karma: +639/-21
Offline Offline

Posts: 5640



blah blah blah

You're the biggest troll out there. It's hard to take anything you say seriously.
Logged

Please, ask all questions on the forums! Doing so will ensure the next person with the same issue gets the opportunity to learn from your experience!

Email/Google chat:
DDillenger84(at)gmail(dot)com

Email>PM
k0mpresd
Hero Member
*****

Karma: +146/-54
Offline Offline

Posts: 1655



derp.

all that coming from the same guy that doesnt know what a usb cable is?
http://forums.vwvortex.com/showthread.php?6031466-USB-part-of-Maestro-cable-worn-out-check-this-out
Logged
jackson.amrol@gmail.com
Full Member
***

Karma: +4/-6
Offline Offline

Posts: 128


"you sir are an animal"


WWW

Guys, guys.. Don't roast him too hard, he'll go back to work tomorrow and molest grandma's extra hard..
Logged

Lost, No.. My minds around here somewhere..
Shh, I'm calling my mom.. "It's 3AM" SHH!
Mom, is there such a thing as kosher pork?
"I'm not bailing you out tonight"...
jackson.amrol@gmail.com
Full Member
***

Karma: +4/-6
Offline Offline

Posts: 128


"you sir are an animal"


WWW

Wait.. That's TSA, The Department of Homeland Security has a vital mission: to secure the nation from the many threats we face.. Mexicans and Marijuana..
Logged

Lost, No.. My minds around here somewhere..
Shh, I'm calling my mom.. "It's 3AM" SHH!
Mom, is there such a thing as kosher pork?
"I'm not bailing you out tonight"...
Pages: [1] 2
  Print  
 
Jump to:  

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines Page created in 0.025 seconds with 16 queries. (Pretty URLs adds 0s, 0q)